US2025286861A1PendingUtilityA1

Service optimization in networks and cloud interconnects

Assignee: CISCO TECH INCPriority: Nov 30, 2022Filed: May 22, 2025Published: Sep 11, 2025
Est. expiryNov 30, 2042(~16.3 yrs left)· nominal 20-yr term from priority
H04L 63/0428H04L 63/0245H04L 63/0209H04L 63/0227H04L 63/20H04L 63/0263
71
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This disclosure describes techniques and mechanisms for disclosure describes techniques and mechanisms for optimizing firewall enforcement. The techniques may implement a dynamic detection of Layer 7 processing at one end of the network, alleviating the need to enforce another layer 7 firewall inspection at the other end, thereby saving processing and network resources. The techniques enable firewalls and policies to be statically defined and located in one place.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 identifying, by a first network device located at a first site of a network and based on receiving a data packet, a first firewall policy associated with the first network device;   receiving metadata associated with the first firewall policy from a cloud service of the network;   inspecting, based at least in part on the first firewall policy and by a first firewall of the network, the data packet by the first network device;   adding, by the first network device and based on the metadata, a marker to a header of the data packet to indicate inspection by the first firewall, the marker comprising unified threat defense (UTD) metadata; and   transmitting, via the network, the data packet to a second network device at a second site, wherein the second network device refrains from inspecting the data packet based on the UTD metadata.   
     
     
         2 . The method of  claim 1 , wherein the data packet further comprises an initial data packet of a data flow, the method further comprising refraining from adding the marker to subsequent data packets of the data flow. 
     
     
         3 . The method of  claim 1 , wherein the second network device refrains from inspecting the data packet based on:
 extracting, by the second network device, a profile identifier included in the UTD metadata, the profile identifier being applied to the data packet by the first firewall;   identifying, based on the profile identifier, a second firewall policy associated with the second network device;   receiving second metadata associated with the second firewall policy from the cloud service of the network; and   determining, by the second network device, based at least in part on the second firewall policy, the second metadata, and extracting the marker from the header, to refrain from inspecting the data packet.   
     
     
         4 . The method of  claim 1 , wherein refraining from inspecting the data packet comprises refraining from processing a Layer 7 Firewall inspection by the second network device. 
     
     
         5 . The method of  claim 1 , wherein the first network device comprises a software defined cloud interconnect (SDCI) router and the second network device comprises a SDCI headend device. 
     
     
         6 . The method of  claim 1 , wherein the network comprises a software defined cloud interconnect wide area network, and wherein data included in the header of the data packet is encrypted. 
     
     
         7 . The method of  claim 1 , wherein the marker comprises a flag included in the UTD metadata, wherein the flag is included as part of a security level tag length value. 
     
     
         8 . The method of  claim 1 , wherein the UTD metadata is added to a software-defined wide area network header of the data packet in a tag length value format. 
     
     
         9 . The method of  claim 1 , wherein the metadata includes intelligence data indicating whether additional inspections should be performed on the data packet. 
     
     
         10 . A system comprising:
 one or more processors; and   one or more non-transitory computer-readable media storing computer-executable instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:
 identifying, by a first network device located at a first site of a network and based on receiving a data packet, a first firewall policy associated with the first network device; 
 receiving metadata associated with the first firewall policy from a cloud service of the network; 
 inspecting, based at least in part on the first firewall policy and by a first firewall of the network, the data packet by the first network device; 
 adding, by the first network device and based on the metadata, a marker to a header of the data packet to indicate inspection by the first firewall, the marker comprising unified threat defense (UTD) metadata; and 
 transmitting, via the network, the data packet to a second network device at a second site, wherein the second network device refrains from inspecting the data packet based on the UTD metadata. 
   
     
     
         11 . The system of  claim 10 , wherein the data packet further comprises an initial data packet of a data flow, the operations further comprising refraining from adding the marker to subsequent data packets of the data flow. 
     
     
         12 . The system of  claim 10 , wherein the second network device refrains from inspecting the data packet based on:
 extracting, by the second network device, a profile identifier included in the UTD metadata, the profile identifier being applied to the data packet by the first firewall;   identifying, based on the profile identifier, a second firewall policy associated with the second network device;   receiving second metadata associated with the second firewall policy from the cloud service of the network; and   determining, by the second network device, based at least in part on the second firewall policy, the second metadata, and extracting the marker from the header, to refrain from inspecting the data packet.   
     
     
         13 . The system of  claim 10 , wherein refraining from inspecting the data packet comprises refraining from processing a Layer 7 Firewall inspection by the second network device. 
     
     
         14 . The system of  claim 10 , wherein the first network device comprises a software defined cloud interconnect (SDCI) router and the second network device comprises a SDCI headend device. 
     
     
         15 . The system of  claim 10 , wherein the network comprises a software defined cloud interconnect wide area network, and wherein data included in the header of the data packet is encrypted. 
     
     
         16 . The system of  claim 10 , wherein the marker comprises a flag included in the UTD metadata, wherein the flag is included as part of a security level tag length value. 
     
     
         17 . The system of  claim 10 , wherein the UTD metadata is added to a software-defined wide area network header of the data packet in a tag length value format. 
     
     
         18 . The system of  claim 10 , wherein the metadata includes intelligence data indicating whether additional inspections should be performed on the data packet. 
     
     
         19 . One or more non-transitory computer-readable media storing computer-readable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
 identifying, by a first network device located at a first site of a network and based on receiving a data packet, a first firewall policy associated with the first network device;   receiving metadata associated with the first firewall policy from a cloud service of the network;   inspecting, based at least in part on the first firewall policy and by a first firewall of the network, the data packet by the first network device;   adding, by the first network device and based on the metadata, a marker to a header of the data packet to indicate inspection by the first firewall, the marker comprising unified threat defense (UTD) metadata; and   transmitting, via the network, the data packet to a second network device at a second site, wherein the second network device refrains from inspecting the data packet based on the UTD metadata.   
     
     
         20 . The one or more non-transitory computer-readable media of  claim 19 , wherein the second network device refrains from inspecting the data packet based on:
 extracting, by the second network device, a profile identifier included in the UTD metadata, the profile identifier being applied to the data packet by the first firewall;   identifying, based on the profile identifier, a second firewall policy associated with the second network device;   receiving second metadata associated with the second firewall policy from the cloud service of the network; and   determining, by the second network device, based at least in part on the second firewall policy, the second metadata, and extracting the marker from the header, to refrain from inspecting the data packet.

Join the waitlist — get patent alerts

Track US2025286861A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.